Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-35296

Опубликовано: 26 июл. 2024
Источник: debian
EPSS Низкий

Описание

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
trafficserverfixed9.2.5+ds-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2024/07/25/1

  • https://github.com/apache/trafficserver/commit/4122abd9272d49cb4ed87d479e1febb0f1c7c1da

EPSS

Процентиль: 32%
0.00123
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 1 года назад

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

CVSS3: 8.2
nvd
больше 1 года назад

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

CVSS3: 8.2
github
больше 1 года назад

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость веб-сервера Apache Traffic Server, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольные запросы

EPSS

Процентиль: 32%
0.00123
Низкий